Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cassianetworks

First CVE: Oct 14, 2022Active for: 4 yearsTotal CVEs: 5

Cassianetworks develops a focused product line of Bluetooth access controllers and related firmware, including models such as the XC1000 and XC2000, that manage wireless device connectivity in enterprise environments. Its disclosed vulnerabilities cluster around web-application and authentication boundaries—cross-site request forgery, improper authentication, path traversal, command injection, and incorrect permission assignment—reflecting the management interface and device-access control surfaces that characterize this class of networked appliance. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
5
Total CVEs
More Total CVEs than 83% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cassianetworks over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 14, 2022
3 years ago
Most Recent CVE
Jan 10, 2024
926 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-31446CRITICAL
In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and exe
Jan 10, 20249.873NOYES
CVE-2023-35793HIGH
An issue was discovered in Cassia Access Controller 2.1.1.2303271039. Establishing a web SSH session to gateways is vulnerable to Cross Site Request Forgery (CSRF) attacks.
Sep 27, 20238.825NONO
CVE-2021-22685HIGH
An attacker may be able to use minify route with a relative path to view any file on the Cassia Networks Access Controller prior to 2.0.1.
Oct 14, 20227.525NONO
CVE-2023-35794HIGH
An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) can be accessed without authentication. Specifically, there is
Oct 27, 20238.824NONO
CVE-2023-31445MEDIUM
Cassia Access controller before 2.1.1.2203171453, was discovered to have a unprivileged -information disclosure vulnerability that allows read-only users have the ability to enumer
May 11, 20235.319NONO
View all 5 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products5 CVEs
20%
60%
20%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (80.0%)
Unknown0 (0.0%)
Required1 (20.0%)
Privileges Required
Low1 (20.0%)
High0 (0.0%)
None4 (80.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
20.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cassianetworks.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cassianetworks — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cassianetworks's Products

View all 2 CNAs →

Top CWEs